Supply-chain incident feed

What we've been watching.

Recent supply-chain compromises across npm, PyPI, RubyGems, crates.io, Go modules, Packagist, NuGet, Open VSX, Docker Hub, and GitHub Actions. Curated from public vendor advisories. We list every version we can verify so the scanner picks them up directly: 511 package–version pairs across 36 incidents and counting.

Sources cited per card. We only list package versions named by the original advisory; we don't infer compromises. Missing something? Send it in.